boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-25550

Seagull Software BarTender Unauthenticated RCE via .NET Remoting Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0142   72.0     —
AFFECTED
  Product         Versions     Fixed
  BarTender 2010  unspecified  —
  BarTender 2016  unspecified  —
  BarTender 2019  unspecified  —
TIMELINE
  Feb 2   Reserved by VulnCheck
  Jun 4   Published (CNA: VulnCheck)
  Sep 2   EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.
  Sep 16  EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.
CWE-306, CWE-502 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Awaiting Analysis

Description

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singleton endpoint — BarTenderSystem for BarTender 2016 <= R9, and DataServiceSingleton for BarTender 2019 <= R10 — configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling to read or write arbitrary files on the server using the .NET WebClient class, or coerce NTLMv2 authentication by supplying a UNC path to an attacker-controlled server, enabling sensitive credential disclosure, remote code execution, or lateral movement depending on service account privileges and network environment. The service runs in the context of NT AUTHORITY\\SYSTEM. This vulnerability is corrected in BarTender 12.0.1. Users of affected releases should upgrade to BarTender 12.0.1 or later.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
February 2, 2026ReservedReserved by VulnCheck
June 4, 2026PublishedPublished (CNA: VulnCheck)
September 2, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.
September 16, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Seagull Software, LLC.BarTender 2010———
Seagull Software, LLC.BarTender 2016———
Seagull Software, LLC.BarTender 2019———

Weaknesses

CWE-306 · CWE-502

References (4)

Related

Authoritative record: CVE-2026-25550 at cve.org

Vendors: seagull software

Weaknesses: CWE-306 · CWE-502

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-25550 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.